WordPress Plugin Vulnerabilities
Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated Attachment ID Reparenting
Description
The plugin does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
PO-WEI TING (Dinlon5566), Open Information Security Inc.
Submitter
PO-WEI TING (Dinlon5566)
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-17 (about 9 hours ago)
Added
2026-09-17 (about 1 hour ago)
Last Updated
2026-09-17 (about 1 hour ago)